CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,707 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-09
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-4095 EXP | Directory traversal vulnerability in connector.php in the fckeditor2rc2 addon in DoceboLMS 2.0.4 allows remote attackers to list arbitrary files and d… | Patch early | 5.0 medium | 8.5% | 2005-12-08 |
| CVE-2009-0172 EXP | Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infini… | Patch early | 5.0 medium | 8.5% | 2009-01-16 |
| CVE-2011-1571 EXP | Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used,… | Patch early | 6.8 medium | 8.5% | 2011-05-07 |
| CVE-2002-0769 EXP | The web-based configuration interface for the Cisco ATA 186 Analog Telephone Adaptor allows remote attackers to bypass authentication via an HTTP POST… | Patch early | 6.4 medium | 8.5% | 2002-08-12 |
| CVE-2007-1375 EXP | Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value… | Patch early | 5.0 medium | 8.5% | 2007-03-10 |
| CVE-2011-2132 EXP | Adobe Flash Media Server (FMS) before 3.5.7, and 4.x before 4.0.3, allows attackers to cause a denial of service (memory corruption) via unspecified v… | Patch early | 5.0 medium | 8.5% | 2011-08-11 |
| CVE-2012-4253 EXP | Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) langua… | Patch early | 4.3 medium | 8.5% | 2012-08-13 |
| CVE-2017-1000499 EXP | phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to… | Patch early | 8.8 high | 8.5% | 2018-01-03 |
| CVE-2017-6020 EXP | Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize external in… | Patch early | 5.3 medium | 8.5% | 2018-04-17 |
| CVE-2014-2880 EXP | Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows rem… | Patch early | 5.8 medium | 8.5% | 2014-04-17 |
| CVE-2011-2702 EXP | Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization, allows… | Patch early | 6.8 medium | 8.5% | 2014-10-27 |
| CVE-2015-8566 EXP | The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspecified session values. | Patch early | 7.5 high | 8.5% | 2015-12-16 |
| CVE-2006-3102 EXP | Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execute arbitra… | Patch early | 5.1 medium | 8.5% | 2006-06-21 |
| CVE-2007-5984 EXP | classes/Url.php in Justin Hagstrom AutoIndex PHP Script before 2.2.4 allows remote attackers to cause a denial of service (CPU and memory consumption)… | Patch early | 7.8 high | 8.5% | 2007-11-15 |
| CVE-2002-0266 EXP | Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexistent file, which generates an… | Patch early | 5.0 medium | 8.5% | 2002-05-29 |
| CVE-2002-1483 EXP | db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filena… | Patch early | 5.0 medium | 8.5% | 2003-04-22 |
| CVE-2017-9640 EXP | A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1… | Patch early | 6.3 medium | 8.5% | 2017-08-25 |
| CVE-2010-4181 EXP | Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequences. | Patch early | 5.0 medium | 8.5% | 2010-11-04 |
| CVE-2009-2110 EXP | Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arb… | Patch early | 7.6 high | 8.4% | 2009-06-18 |
| CVE-2006-0644 EXP | Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 allow remote attackers to includ… | Patch early | 7.5 high | 8.4% | 2006-02-10 |
| CVE-2008-2292 EXP | Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for Perl, allows remote attackers… | Patch early | 6.8 medium | 8.4% | 2008-05-18 |
| CVE-2021-21337 EXP | Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 th… | Patch early | 5.7 medium | 8.4% | 2021-03-08 |
| CVE-1999-1557 EXP | Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service a… | Patch early | 5.0 medium | 8.4% | 2005-05-02 |
| CVE-2007-1308 EXP | ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessin… | Patch early | 4.3 medium | 8.4% | 2007-03-07 |
| CVE-2015-7571 EXP | Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an executable ex… | Patch early | 7.8 high | 8.4% | 2017-08-07 |
| CVE-2014-8008 EXP | Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authent… | Patch early | 6.8 medium | 8.4% | 2015-01-22 |
| CVE-2009-2473 EXP | neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause… | Patch early | 4.3 medium | 8.4% | 2009-08-21 |
| CVE-2001-0026 EXP | rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option. | Patch early | 5.0 medium | 8.4% | 2001-02-12 |
| CVE-2006-5820 EXP | The LinkSBIcons method in the SuperBuddy ActiveX control (Sb.SuperBuddy.1) in America Online 9.0 Security Edition dereferences an arbitrary function p… | Patch early | 9.3 high | 8.4% | 2007-04-02 |
| CVE-2004-2445 EXP | Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a .. (dot dot) in the gadget param… | Patch early | 5.0 medium | 8.4% | 2004-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt